How to Fund FOSS, Save It from the CRA, and Improve Cybersecurity
gavinhoward.com
gavinhoward.com
Anyways. I don't really understand what the author is talking here. Seems like he is in a very deep forest. Since the fines start from 5 million eur... The CRA is not about FOSS developers, it's mostly about companies who create devices that we use in our everyday lives.
Apple phones do not auto install updates, now they will. Intel will think twice before implementing some untested shit. Companies will react swiftly when something goes sideways inside their product. If you enter the router market you have to provide security updates for a loooong time, and make sure the default password is not "" or admin...
Everyone, literally everyone shat on security, until now.
But the author’s point is that the law as written, would apply to open source as well. It would create liability for open source contributors even if they have no business relationship to those using this software. That seems bad and it seems like it would greatly benefit deeply pocketed private software companies.
Usually what is kind of gray zone is signing delivery contracts as engineer, without having taken the Order admission exam, after finishing the degree.
Bert Huber has a summary for people being interested https://berthub.eu/articles/posts/eu-cra-what-does-it-mean-f...
If you don’t, well, you can quit reading now and pretend ignorance. And don’t let the boot hit you on the way out.
But if you are at least curious, you probably think there is a catch.
I won’t bury it; the catch is this: we must own the responsibility society is trying to give us and act like it! " The German govertment does actually with the Souvereign fund but I think the market based CRA solution is better.
He's LDS.
What problem do you have with the LDS?
How does it affect the hiring, promotion, or retentions in your company?